Bug 31619 - sudo new security issue CVE-2023-27320
Summary: sudo new security issue CVE-2023-27320
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Sysadmin Team
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-03-02 23:30 CET by David Walser
Modified: 2023-03-03 16:58 CET (History)
0 users

See Also:
Source RPM: sudo-1.9.12p2-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-03-02 23:30:24 CET
Sudo has issued an advisory on February 27:
https://www.sudo.ws/security/advisories/double_free/

The issue is fixed upstream in 1.9.13p2:
https://www.sudo.ws/releases/stable/#1.9.13p2

Mageia 8 is not affected.

Ubuntu has issued an advisory for this today (March 2):
https://ubuntu.com/security/notices/USN-5908-1

Freeze move request has been submitted yesterday but it hasn't been moved yet.
Comment 1 David Walser 2023-03-03 16:58:07 CET
sudo-1.9.13p2-1.mga9.src.rpm moved to core/release.

Status: NEW => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.